CVE-2026-74820

Published Aug 27, 2026

Last updated 2 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-74820 is a SQL injection vulnerability discovered within the ServiceNow AI platform. This flaw could allow an unauthenticated user, under specific circumstances, to execute arbitrary SQL statements against the underlying database of a ServiceNow instance. Successful exploitation of this vulnerability could lead to unauthorized access or modification of instance data beyond intended permissions. ServiceNow has addressed this issue by deploying security updates to hosted instances and providing updates to partners and self-hosted customers.

Description
ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended.  ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. We are not currently aware of malicious exploitation against ServiceNow instances.  We recommend customers promptly apply appropriate updates or upgrade to a patched release if they have not already done so.
Source
psirt@servicenow.com
NVD status
Received

Risk scores

CVSS 4.0

Type
Secondary
Base score
10
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-89

Social media

Hype score
Not currently trending
  1. https://t.co/XGyPIY3VaE ServiceNow has remediated a SQL injection vulnerability a code injection vulnerability a sandbox escape security issue CVE-2026-6876, CVE-2026-18886, CVE-2026-74820 #ITSecurity

    @seaarepea

    30 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. ServiceNow'da üç kritik (CVSS 10.0) güvenlik açığı! Bulunan açıklardan CVE-2026-18885 kod çalıştırmaya, CVE-2026-18886 yetki yükseltmeye, CVE-2026-74820 ise SQL enjeksiyonuyla veri okuma ve değiştirmeye izin veriyor. https://t.co/fE5KzEEpii https://t.co/lPOHizxF

    @Siber_Bulten

    30 Aug 2026

    807 Impressions

    0 Retweets

    0 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  3. August 2026 CVE Advisory Notification - Security - Now Support Portal What you need to know: On August 27, 2026, ServiceNow issued CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820 regarding the underlying logic that allowed for the reported security issues. If

    @VistemSolutions

    30 Aug 2026

    38 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ServiceNow patched three CVSS 10.0 vulnerabilities August 28. All three: unauthenticated code injection or SQL injection in the AI Platform. CVE-2026-18885, CVE-2026-18886, CVE-2026-74820. Every internet-facing instance vulnerable until patched. #Cybersecurity

    @McM1Alex

    29 Aug 2026

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Security Bulletin: Multiple Critical Vulnerabilities in ServiceNow AI Platform - Three critical ServiceNow AI Platform vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) may enable code injection, privilege escalation, or SQL inj... https://t.co/HQsgwH5UTu

    @RedLegg

    28 Aug 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 ServiceNow just disclosed 3 CVSS 10.0 vulnerabilities that need immediate attention. No authentication. No user interaction. Low attack complexity. CVE-2026-18885 can enable arbitrary code execution. CVE-2026-18886 can enable privilege escalation. CVE-2026-74820 can enable

    @thecybersecguru

    28 Aug 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 💀 Three ServiceNow AI Platform flaws rated CVSS 10.0 CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 — unauthenticated code & SQL injection in Xanadu/Yokohama releases. 🔗 https://t.co/ZlwhR6wbuo

    @CyberOSINTIO

    28 Aug 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Warning: Multiple vulnerabilities in #ServiceNow. #CVE-2026-6876 #CVE-2026-18885 #CVE-2026-18886 #CVE-2026-74820 CVSS: 8.7 CVSS: 10 These vulnerabilities combined can lead to a full system compromise. Read our advisory: https://t.co/dbEQKPJO28 and #Patch #Patch #Patch

    @CCBalert

    28 Aug 2026

    302 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  9. 🚨🚨🚨 CVE-2026-6876, CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 August 2026 CVE Advisory Notification - Security ServiceNow Posture https://t.co/KsNPftCqPv

    @autumn_good_35

    28 Aug 2026

    314 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. ServiceNow patched CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820, code injection and SQL injection flaws rated CVSS 10, plus a CVSS 8.7 bug. #ServiceNow #CodeInjection #SQLInjection #CVE #InfoSec https://t.co/hgTi9FD49L

    @Daily_CyberSec

    28 Aug 2026

    778 Impressions

    4 Retweets

    9 Likes

    7 Bookmarks

    0 Replies

    0 Quotes